Data Breach Response Policy
Last updated: 11 July 2026
1. Purpose
1.1 This policy sets out how Career Calling International Pty Ltd (ABN 53 162 651 238, ACN/ARBN 162 651 238), trading as CAQA Creative ("we", "us", "our"), prepares for, responds to and notifies data breaches affecting personal information we hold, including information collected through this website (https://caqa-creative-preview.netlify.app).
1.2 It implements our obligations under the Notifiable Data Breaches (NDB) scheme in Part IIIC of the Privacy Act 1988 (Cth), and — where the EU or UK GDPR applies to the affected data — GDPR Articles 33 and 34.
2. What is a data breach?
2.1 A data breach occurs when personal information we hold is subject to unauthorised access, unauthorised disclosure, or loss. Examples include: a lost or stolen device containing personal information; unauthorised access to an email account, database or supplier system; personal information sent to the wrong recipient; and a cyber incident such as ransomware, phishing compromise or website defacement.
2.2 An eligible data breach under the NDB scheme is one where a reasonable person would conclude the breach is likely to result in serious harm to any individual to whom the information relates, and remedial action has not prevented that likelihood.
3. Roles and responsibilities
3.1 The Privacy Officer leads our data breach response and is the single point of contact for breach matters:
- Email: complaints@careercalling.com.au
- Mail: Privacy Officer, Career Calling International Pty Ltd, 2/10 Lawn Court, Craigieburn VIC 3064, Australia
- Telephone: 1800 266 160
3.2 The Privacy Officer may convene a response team including management, IT/hosting personnel, affected service providers and external legal or forensic advisers as the incident requires.
3.3 All staff and contractors must report any suspected breach to the Privacy Officer immediately upon becoming aware of it. Service providers who process personal information for us are required to notify us of breaches affecting our data without undue delay.
4. Response procedure
Step 1 — Identify and report (immediately)
Any suspected breach is reported to the Privacy Officer with all known details: what happened, when, what information and systems are involved, and who may be affected.
Step 2 — Contain (immediately)
We act at once to limit the breach — for example, disabling compromised accounts or credentials, isolating affected systems, recalling misdirected communications, and instructing service providers to contain the incident. Evidence is preserved for assessment.
Step 3 — Assess (within 30 days)
Where it is not immediately clear whether a breach is an eligible data breach, the Privacy Officer conducts a reasonable and expeditious assessment, completed within 30 calendar days of becoming aware of the suspected breach, considering: the type and sensitivity of the information; who may have obtained it and their likely intent; whether protections (such as encryption) apply; the number and vulnerability of affected individuals; and the likelihood and severity of harm (financial, identity, physical, psychological, reputational). Remedial action is taken throughout; if remediation prevents the likelihood of serious harm, notification may not be required.
Step 4 — Notify
- (a) OAIC and affected individuals (Australia). If the breach is an eligible data breach, we prepare a statement and notify the Office of the Australian Information Commissioner (OAIC) as soon as practicable, and notify affected individuals (or, where that is not practicable, publish the statement on our websites) — describing the breach, the information involved, and the steps individuals should take to protect themselves.
- (b) GDPR supervisory authority (EU/UK). Where the GDPR or UK GDPR applies, we notify the competent supervisory authority within 72 hours of becoming aware of the breach, unless it is unlikely to result in a risk to individuals' rights and freedoms; where the risk is high, we also inform affected data subjects without undue delay.
- (c) Other notifications. Where appropriate, we also notify the police or the Australian Cyber Security Centre (cyber incidents), affected US state authorities where state breach-notification laws apply, financial institutions, and any affected partners or suppliers.
Step 5 — Review
After each incident we conduct a post-incident review: root-cause analysis, remediation of vulnerabilities, updates to security controls and this policy, and staff refresher training where indicated.
5. Breach register
The Privacy Officer maintains a confidential register of all data breaches and suspected breaches — including those assessed as not notifiable — recording the incident, assessment, decisions, notifications and remediation. Register entries are retained in accordance with our Data Retention Policy.
6. What you should do
6.1 If you suspect that your personal information held by us has been involved in a breach — for example, you receive a suspicious communication referencing your dealings with CAQA Creative — contact the Privacy Officer immediately using the details in clause 3.1.
6.2 If we notify you of a breach affecting you, we will explain what happened and recommend protective steps, which may include changing passwords, monitoring accounts and statements, and contacting IDCARE (idcare.org · 1800 595 160), Australia's national identity and cyber support service.
6.3 If you are dissatisfied with our handling of a breach, you may complain under our Complaints & Feedback Policy and escalate to the OAIC (www.oaic.gov.au · 1300 363 992), or — for EU/UK residents — your local supervisory authority.
7. Review of this policy
This policy is tested and reviewed at least annually, and after any significant incident or change to applicable law.
